Privacy Policy

Last updated: August 28, 2026

1. Introduction

This Privacy Policy explains how r3Converse ("we", "us" or "our") collects, uses, stores, and protects your personal data when you use our website, dashboard, widget, and related services (collectively, the "Service"). We act as the data controller for the personal data of our customers and end users. We are committed to complying with the General Data Protection Regulation (GDPR) for users in the European Union, the Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) for users in Spain, and other applicable data protection laws.

2. Data Controller

r3Converse is the data controller of your personal data. Contact email: privacy@r3converse.com If you have questions about how we process your personal data, you can contact our Data Protection Officer (DPO) at the same address.

3. Information We Collect

We collect and process the following categories of personal data: • Account and contact data: name, email address, company name, billing address, and payment information processed by our payment provider. • Conversation data: messages exchanged through the chatbot widget, including visitor questions, lead details, project descriptions, and any other information voluntarily shared by the visitor. • Lead and proposal data: names, emails, phone numbers, project requirements, budget, timeline, and proposal status. • Usage data: feature usage, login history, and widget interactions required to provide the Service. • Cookies and similar technologies: data collected through cookies and local storage to keep you logged in and remember preferences. We do not use analytics or marketing cookies.

4. How We Use Your Data

We use your personal data for the following purposes: • To provide and maintain the Service, including hosting your widget, processing conversations, generating proposals, and managing your account. • To improve our AI models and service quality, including analyzing conversation patterns and error logs. • To process payments, manage subscriptions, and send billing notifications. • To communicate with you about your account, service updates, security alerts, and marketing communications (where permitted). • To ensure security, prevent fraud, and comply with legal obligations.

5. Legal Basis for Processing

We process personal data based on the following legal grounds: • Performance of a contract / request of the data subject: processing necessary to respond to chat messages, manage your account, and deliver the Service under our Terms of Service. • Legitimate interest: improving service quality, ensuring security, preventing fraud, and qualifying website visitors as leads for our customers. • Consent: where required, for example for marketing communications. We do not use non-essential cookies. • Legal obligation: compliance with tax, accounting, and data protection laws. Visitors who interact with the widget provide their data voluntarily. By starting a conversation, they acknowledge that their messages will be processed to receive a response and, where applicable, to be qualified as a lead.

6. Data Retention Periods

We retain personal data only for as long as necessary for the purposes described in this policy: • Account data: retained while your account is active. If you request deletion, we will delete your account data within 30 days, except where retention is necessary for legal or billing purposes. • Conversation, lead and proposal data: retained while your account is active. You can delete individual records from your dashboard at any time. If you request account deletion, we will delete these data within 30 days, except where anonymized retention is required by law. • Billing data: retained for 6 years to comply with tax and accounting regulations. • Backup copies: backups may retain deleted data for up to 90 days after deletion from active systems.

7. Recipients and International Transfers

We do not sell your personal data. We only share it with trusted service providers who help us operate the Service. Our main sub-processors are: • Cloud hosting and infrastructure providers: located in the European Union where possible; they host our servers, PostgreSQL database and Redis cache. • AI processing: messages sent through the widget are processed in the European Union to generate responses. Currently, no personal data is transferred outside the European Economic Area for AI processing. • Payment processors (Dodo Payments): process billing and subscription data. Some data may be transferred to the United States; Dodo Payments provides appropriate safeguards under its Terms of Service. • Email communication providers (Zoho Mail): process email address and message content to send transactional and service emails. Enterprise customers can use their own AI provider key (BYOK) to keep direct control over AI processing. All third-party processors are contractually bound to process data only on our instructions and to maintain adequate security measures.

8. Your Rights

Under the GDPR and LOPDGDD, you have the following rights regarding your personal data: • Right of access: obtain confirmation about whether we process your data and request a copy. • Right to rectification: correct inaccurate or incomplete data. • Right to erasure ("right to be forgotten"): request deletion of your data when it is no longer necessary. • Right to restriction: request limitation of processing in certain circumstances. • Right to object: object to processing based on legitimate interest or direct marketing. • Right to data portability: receive your data in a structured, commonly used format. • Right to withdraw consent: withdraw consent at any time, without affecting the lawfulness of processing based on consent before withdrawal. To exercise your rights, contact us at privacy@r3converse.com. We will respond within 30 days.

9. Security Measures

We implement technical and organizational measures to protect your data, including: • Encryption in transit using TLS/SSL. • Row-level security and tenant isolation in the database. • AES-256-GCM encryption for API keys and sensitive configuration. • Access controls and role-based permissions. • Regular automated backups. Despite these measures, no system is completely secure. We will notify you and the relevant supervisory authority of any data breach in accordance with applicable law.

10. Minors

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have collected data from a minor, please contact us so we can delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before they take effect, unless a shorter period is required by law.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: Email: privacy@r3converse.com We are committed to resolving any privacy-related issues in a timely and transparent manner.